Cisco NX-OS Software Sensitive Log Information Disclosure Vulnerability

🚨 SEVERITY: MEDIUM — CVSS 5.5 Security Advisory

TL;DR 📌

A medium severity vulnerability has been identified in Cisco NX-OS Software that could allow an authenticated, local attacker to access sensitive log information. No workarounds are available, and Cisco has released fixed software to address this issue.

What happened 🕵️‍♂️

A vulnerability in the logging feature of Cisco NX-OS Software affects several Cisco Nexus and UCS devices. This vulnerability arises from improper logging of sensitive information, which could allow an authenticated local attacker to access sensitive data, including stored credentials, by exploiting the log files on the device’s file system.

Affected products 🖥️

The following Cisco products are affected by this vulnerability:

  • Nexus 3000 Series Switches
  • Nexus 9000 Series Switches in standalone NX-OS mode
  • UCS 6400 Series Fabric Interconnects
  • UCS 6500 Series Fabric Interconnects
  • UCS X-Series Direct Fabric Interconnect 9108 100G

Fixed software 🔧

Upgrade to the first fixed release in your train (or later):

Release / Product First Fixed Release Notes
4.1 and earlier Migrate to a fixed release.
4.2 4.2(3p)
4.3 4.3(6c)
6.0 Not vulnerable.
1.0 Initial public release.

Workarounds 🧯

There are no workarounds available to mitigate this vulnerability.

Risk in context 🎯

The vulnerability has a CVSS score of 5.5, categorizing it as Medium severity. The risk is primarily driven by the requirement for local authentication, meaning that an attacker must have access to the device’s file system to exploit the vulnerability. While the potential impact includes exposure of sensitive information, the lack of public exploitation reports suggests that immediate risk may be limited.

Fast facts ⚡

  • Vulnerability ID: CVE-2025-20290
  • CVSS Score: 5.5 (Medium)
  • Affected Products: Nexus 3000, Nexus 9000, UCS 6400, UCS 6500, UCS 9108
  • Workarounds: None available
  • Fixed Software: Updates released, specific versions not listed

For leadership 🧭

Executive summary. A logging flaw in Cisco NX-OS writes sensitive data, including stored credentials, into on-device log files that any authenticated local user can read on affected Nexus and UCS Fabric Interconnect gear. There is no workaround, so patching on the next available maintenance window is the only real fix.

Why it matters:

  • Affects core switching and fabric interconnect hardware: Nexus 3000, Nexus 9000 (standalone NX-OS mode), UCS 6400, UCS 6500, and UCS X-Series 9108 Fabric Interconnects.
  • Exposed data includes stored credentials, so any local account with log file access could harvest secrets and move further into the network without needing to exploit anything else.
  • No workaround exists, meaning devices stay exposed to this logging behaviour until the fixed NX-OS release is installed.
  • Devices on 4.1 or earlier have no direct patch path and require migration to a supported train, which is a bigger change than a simple version bump.

Now / Next / Later:

  • Now: Identify every Nexus 3000/9000 and UCS 6400/6500/9108 Fabric Interconnect running NX-OS and check which release train each is on.
  • Next: Schedule upgrades to the first fixed release for each train (4.2(3p) for 4.2, 4.3(6c) for 4.3) or plan migration off 4.1 and earlier during the next maintenance window.
  • Later: Review who holds local authenticated access to these devices and tighten log file permissions and account provisioning so fewer people can read historical log data by default.